Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: otdih-v-odesse.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Jan 2015 18:33:07 GMT
Server: nginx/1.6.0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://otdih-v-odesse.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: otdih-v-odesse.ru
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Jan 2015 18:33:07 GMT
Server: nginx/1.6.0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://otdih-v-odesse.ru/xmlrpc.php
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: otdih-v-odesse.ru
Referer: http://www.google.com/search?q=otdih-v-odesse.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: otdih-v-odesse.ru
Referer: http://www.google.com/search?q=otdih-v-odesse.ru
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://otdih-v-odesse.ru/ | 200 OK Content-Length: 37949 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js | 200 OK Content-Length: 93868 Content-Type: text/javascript | clean |
http://vkontakte.ru/js/api/openapi.js?88 | 200 OK Content-Length: 64063 Content-Type: application/x-javascript | clean |
http://otdih-v-odesse.ru/wp-content/themes/otdih/js/jquery.ui.core.min.js | 200 OK Content-Length: 4295 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/themes/otdih/js/jquery.ui.widget.min.js | 200 OK Content-Length: 3189 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/themes/otdih/js/jquery.ui.mouse.min.js | 200 OK Content-Length: 2803 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/themes/otdih/js/jquery.ui.slider.min.js | 200 OK Content-Length: 9821 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/themes/otdih/js/my.js | 200 OK Content-Length: 5075 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/themes/otdih/js/fancybox.js | 200 OK Content-Length: 27202 Content-Type: application/javascript | clean |
http://cloud.github.com/downloads/malsup/cycle/jquery.cycle.all.latest.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 16 Jan 2015 18:33:11 GMT Via: 1.1 954e53c2911d47d729ae27754b6408a8.cloudfront.net (CloudFront) Location: https://cloud.github.com/downloads/malsup/cycle/jquery.cycle.all.latest.js Server: CloudFront Content-Length: 183 Content-Type: text/html X-Amz-Cf-Id: 1jWPagFFPRaZc2XBUhvZG65znEznCkkiFmhzmc4uiLK97iMqzMwwcg== X-Cache: Redirect from cloudfront | clean |
https://cloud.github.com/downloads/malsup/cycle/jquery.cycle.all.latest.js | 403 Forbidden Content-Length: 231 Content-Type: application/xml | clean |
http://cloud.github.com/test404page.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 16 Jan 2015 18:33:12 GMT Via: 1.1 795b65ff0c55e70d8791f9def508f3a8.cloudfront.net (CloudFront) Location: https://cloud.github.com/test404page.js Server: CloudFront Content-Length: 183 Content-Type: text/html X-Amz-Cf-Id: 0ULVfpcmXow0r8MnIx6KZyZfed0y3b-o2IJ48lqUJBf0wt9qyCtQkA== X-Cache: Redirect from cloudfront | clean |
https://cloud.github.com/test404page.js | 403 Forbidden Content-Length: 243 Content-Type: application/xml | clean |
http://www.antimath.info/demos/cycle-carousel/plugins.js | 200 OK Content-Length: 2401 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-includes/js/jquery/jquery.js?ver=1.7.1 | 200 OK Content-Length: 93889 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/plugins/fancy-box/jquery.fancybox.js?ver=1.2.6 | 200 OK Content-Length: 9522 Content-Type: application/javascript | clean |
http://otdih-v-odesse.ru/wp-content/plugins/fancy-box/jquery.easing.js?ver=1.3 | 200 OK Content-Length: 8097 Content-Type: application/javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=otdih-v-odesse.ru
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://otdih-v-odesse.ru/
Result: otdih-v-odesse.ru is not infected or malware details are not published yet.
Result: otdih-v-odesse.ru is not infected or malware details are not published yet.